token issue --overlay-key records the key the machine made, binds the token to it, gives the machine its address and makes it a peer of the hub, pushing the hub before the token is shown. The token carries the hub's tunnel and the bus at its holder's address on the private network, and enrolment refuses any other key (novox/hq ADR 0169). The bus is no longer public, so a machine outside the mesh can join only this way; a token without a key is still what the machine running the bus joins its own mesh with. Also a token verb, which says it replaces running the command by hand and adding a peer to the hub with wg.
134 lines
3.0 KiB
JSON
134 lines
3.0 KiB
JSON
{
|
|
"module": "mesh-controller",
|
|
"version": "1",
|
|
"slug": "control",
|
|
"claims": [
|
|
{
|
|
"name": "mesh-controller",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"accesses": [
|
|
{
|
|
"path": "/var/lib/mesh-broker-tls",
|
|
"mode": "read"
|
|
}
|
|
],
|
|
"own-secrets": {
|
|
"inventory": "${dir:mesh-state}/inventory",
|
|
"identity": "${dir:mesh-state}/identity",
|
|
"licences": "${dir:mesh-state}/licences",
|
|
"broker": "${dir:mesh-state}/broker",
|
|
"broker-management": "${dir:mesh-state}/broker-management",
|
|
"broker-address": "${dir:mesh-state}/broker-address",
|
|
"bus": "${dir:mesh-state}/bus"
|
|
},
|
|
"secrets-owner": "mesh-controller",
|
|
"prepares": true,
|
|
"tools": [
|
|
"tools",
|
|
"calls",
|
|
"status",
|
|
"nodes",
|
|
"node",
|
|
"modules",
|
|
"seats",
|
|
"builds",
|
|
"plans",
|
|
"delivery-plan",
|
|
"delivery-order",
|
|
"delivery-check",
|
|
"deliver",
|
|
"delivery-stop",
|
|
"delivery-walks",
|
|
"plan",
|
|
"assign",
|
|
"unassign",
|
|
"pin",
|
|
"unpin",
|
|
"push",
|
|
"rotate",
|
|
"issue",
|
|
"token",
|
|
"settings",
|
|
"command",
|
|
"queue",
|
|
"cancel",
|
|
"clear",
|
|
"rebuild",
|
|
"replay",
|
|
"kill",
|
|
"pause",
|
|
"resume",
|
|
"hand-act",
|
|
"drill",
|
|
"hand-acts",
|
|
"durations",
|
|
"conditions",
|
|
"healers",
|
|
"doctor",
|
|
"upgrade",
|
|
"bus",
|
|
"retire",
|
|
"cleanup",
|
|
"data",
|
|
"build"
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "account",
|
|
"type": "user",
|
|
"name": "mesh-controller",
|
|
"shell": "/usr/bin/nologin",
|
|
"home": "/var/lib/mesh-controller"
|
|
},
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "mesh",
|
|
"owner": "mesh-controller"
|
|
},
|
|
{
|
|
"id": "controller",
|
|
"type": "process",
|
|
"name": "mesh-controller",
|
|
"artifact": "controller",
|
|
"run": [
|
|
"./mesh-controller",
|
|
"serve"
|
|
],
|
|
"user": "mesh-controller",
|
|
"env": {
|
|
"MESH_BROKER_CERTIFICATE": "/var/lib/mesh-broker-tls/tls.crt",
|
|
"MESH_STORE_INVENTORY_FILE": "${dir:mesh-state}/inventory",
|
|
"MESH_STORE_IDENTITY_FILE": "${dir:mesh-state}/identity",
|
|
"MESH_STORE_LICENCES_FILE": "${dir:mesh-state}/licences",
|
|
"MESH_BROKER_MANAGEMENT_FILE": "${dir:mesh-state}/broker-management",
|
|
"MESH_BROKER_ADDRESS_FILE": "${dir:mesh-state}/broker-address",
|
|
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_STORE_IDENTITY_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_STORE_LICENCES_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_BROKER_MANAGEMENT_PORT": "${seat:mesh-broker:15672}",
|
|
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}",
|
|
"MESH_BUS_NATS_FILE": "${dir:mesh-state}/bus"
|
|
},
|
|
"replaces": [
|
|
"server"
|
|
]
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "controller",
|
|
"kind": "bundle",
|
|
"language": "go",
|
|
"system": "arch",
|
|
"from": "cmd/mesh-controller",
|
|
"binary": "mesh-controller"
|
|
}
|
|
]
|
|
}
|
|
}
|